Cross-site Scripting Vulnerability in WP Thumbtack Review Slider by jgwhite33
CVE-2025-58216
5.9MEDIUM
What is CVE-2025-58216?
An input validation flaw in the WP Thumbtack Review Slider plugin by jgwhite33 enables attackers to exploit stored Cross-site Scripting (XSS) vulnerabilities. This occurs when the plugin improperly handles input during the generation of web pages, allowing malicious scripts to be injected and stored within the application. When executed in the context of a user's session, these scripts can lead to unauthorized actions, data leakage, and compromised user accounts. Affected versions range from n/a up to 2.6, necessitating immediate attention from site administrators to mitigate risks associated with this vulnerability.
Affected Version(s)
WP Thumbtack Review Slider <= 2.6